A 29-year-old Polish man has been charged in connection with a data breach that exposed the personal details of around 2.5 million customers of the popular Polish e-commerce website Morele.net. Read more in my article on the Hot for Security blog.
Category: Data loss
data breach, Data loss, ESA, Europe, Global Security News, Guest blog
European Space Agency’s cybersecurity in freefall as yet another breach exposes spacecraft and mission data
It has just been a few weeks since reports emerged of the Christmas cyber attack suffered by the European Space Agency (ESA), and the situation has already become worse. Read more in my article on the Hot for Security blog.
AI, Data loss, Global Security News, Google, Instagram, Law & order
Smashing Security podcast #451: I hacked the government, and your headphones are next
In episode 451 of “Smashing Security,” we meet the cybercriminal who hacked the US Supreme Court, Veterans Affairs, and more – and then helpfully posted screenshots (and even someone’s blood type) on an account called “I hacked the government.” Plus we discuss how researchers uncovered a creepy flaw that lets attackers hijack wireless headphones, listen…
BreachForums, data breach, Data loss, Global Security News, Guest blog, ShinyHunters
Hackers get hacked, as BreachForums database is leaked
Have you ever stolen data, traded a hacking tool, or just lurked on a dark web forum believing that you are anonymous? If so, I might have some unsettling news for you. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, privacy, vulnerability
pcTattletale founder pleads guilty in rare stalkerware prosecution
The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, privacy, vulnerability
pcTattletale founder pleads guilty in rare stalkerware prosecution
The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, privacy, vulnerability
pcTattletale founder pleads guilty in rare stalkerware prosecution
The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, privacy, vulnerability
pcTattletale founder pleads guilty in rare stalkerware prosecution
The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, privacy, vulnerability
pcTattletale founder pleads guilty in rare stalkerware prosecution
The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, privacy, vulnerability
pcTattletale founder pleads guilty in rare stalkerware prosecution
The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, privacy, vulnerability
pcTattletale founder pleads guilty in rare stalkerware prosecution
The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, privacy, vulnerability
pcTattletale founder pleads guilty in rare stalkerware prosecution
The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, privacy, vulnerability
pcTattletale founder pleads guilty in rare stalkerware prosecution
The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, privacy, vulnerability
pcTattletale founder pleads guilty in rare stalkerware prosecution
The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, privacy, vulnerability
pcTattletale founder pleads guilty in rare stalkerware prosecution
The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, privacy, vulnerability
pcTattletale founder pleads guilty in rare stalkerware prosecution
The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, privacy, vulnerability
pcTattletale founder pleads guilty in rare stalkerware prosecution
The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog.
Coinbase, CryptoCurrency, data breach, Data loss, Global Security News, Guest blog
Coinbase insider who sold customer data to criminals arrested in India
Police in India have arrested a former Coinbase customer service agent who is believed to have been bribed by cybercriminal gangs to access sensitive customer information. Read more in my article on the Hot for Security blog.
Amazon, Data loss, Europe, Global Security News, Podcast, Ransomware, vulnerability
Smashing Security podcast #448: The Kindle that got pwned
Think your Kindle is harmless? Think again! In this episode, we unpack a Black Hat Europe talk revealing how a boobytrapped audiobook could exploit the Amazon eBook reader – potentially letting an attacker break into your account and seize control of your credit card. Plus a blast from 2021’s “summer of ransomware” returns to haunt…
AI, Data loss, Global Security News, Guest blog, phishing, Security threats
Gartner tells businesses to block AI browsers now
Analyst firm Gartner has issued a blunt warning to organizations: Agentic AI browsers introduce serious new security risks and should be blocked “for the foreseeable future.” Read more in my article on the Fortra blog.
data breach, Data loss, Global Security News, Guest blog, Ireland
Four years later, Irish health service offers €750 to victims of ransomware attack
Remember when a notorious ransomware gang hit the Irish Health Service back in May 2021? Four years on, and it seems victims who had their data exposed will finally receive compensation. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, malware, Podcast, privacy, Security threats
Smashing Security podcast #446: A hacker doxxes himself, and social engineering-as-a-service
A teenage cybercriminal posts a smug screenshot to mock a sextortion scammer… and accidentally hands over the keys to his real-world identity. Meanwhile, we look into the crystal ball for 2026 and consider how stolen data is now the jet fuel of cybercrime – and how next year could be even nastier than 2025. Plus,…
data breach, Data loss, Global Security News, Guest blog, malware, Ransomware
Asahi cyber attack spirals into massive data breach impacting almost 2 million people
Asahi Group Holdings, the makers of the popular Japanese beer Asahi Super Dry, has confirmed that the ransomware attack that disrupted its operations in late September also saw a significant data breach that affects more than 1.5 million customers and approximately 275,000 current and former employees and their families. Read more in my article on…
Data loss, Global Security News, Guest blog, Law & order, malware, Mobile
State-backed spyware attacks are targeting Signal and WhatsApp users, CISA warns
CISA, the US Cybersecurity and Infrastructure Security Agency, has issued a new warning that cybercriminals and state-backed hacking groups are using spyware to compromise smartphones belonging to users of popular encrypted messaging apps such as Signal, WhatsApp, and Telegram. Read more in my article on the Hot for Security blog.
crowdstrike, data breach, Data loss, Global Security News, Podcast
Smashing Security podcast #445: The hack that brought back the zombie apocalypse
America’s airwaves are haunted by zombies again, as we dig into a decade of broadcasters leaving their hardware open to attack, giving hackers the chance to hijack TV shows, blast out fake emergency alerts, and even replace religious sermons with explicit furry podcasts. Meanwhile, we look at how a worker at a cybersecurity firm allegedly…
AI, Artificial Intelligence, Data loss, Global Security News, Guest blog, Security threats
Shadow AI security breaches will hit 40% of all companies by 2030, warns Gartner
Shadow AI – the use of artificial intelligence tools by employees without a company’s approval and oversight – is becoming a significant cybersecurity risk. Read more in my article on the Fortra blog.
Data loss, Global Security News, malware, Podcast, privacy
Smashing Security podcast #444: We’re sorry. Wait, did a company actually say that?
Stop the press – a company has actually said “sorry” after a data breach, and hotels are helping hackers phish their own guests. We examine a refreshingly honest breach response (and why legacy systems are still going to ruin your week), dig into a nasty hotel-booking malware campaign that abuses trust in apps and CAPTCHAs,…
data breach, Data loss, extortion, Global Security News, Guest blog, Ransom
A miracle: A company says sorry after a cyber attack – and donates the ransom to cybersecurity research
One of the sad truths about this world of seemingly endless hacks and data breaches is that companies just won’t apologise. Even when customers, partners, and employees are left wondering when their data will be published by malicious hackers on the dark web, breached organisations will seemingly do everything they can to avoid saying what…
AI, api, Artificial Intelligence, Data loss, Global Security News, Guest blog
Leading AI companies accidentally leak their passwords and digital keys on GitHub – what you need to know
Many of the world’s top artificial intelligence companies are making a simple but dangerous mistake. They are accidentally publishing their passwords and digital keys on GitHub, the popular code-sharing website that is used by millions of developers every day. Read more in my article on the Fortra blog.
Data loss, Global Security News, Guest blog, Law & order, malware
“Pay up or we share the tapes”: Hackers target massage parlour clients in blackmail scheme
South Korean police have uncovered a hacking operation that stole sensitive data from massage parlours and blackmailed their male clientele. Read more in my article on the Hot for Security blog.
data breach, Data loss, Global Security News, Law & order
The human cost of the UK Government’s Afghan data leak
Can data leaks do real harm? Yes, they can. And so can a failure to respond appropriately.
Data loss, Global Security News, Law & order, Podcast, privacy, vulnerability
Smashing Security podcast #441: Inside the mob’s million-dollar poker hack, and a Formula 1 fumble
Basketball stars have allegedly joined forces with the mafia to fleece high-rollers in a poker scam involving hacked shufflers, covert cameras, and an X-ray card table. Meanwhile, researchers have found they could poke around an FIA driver portal to pull up the personal details of Formula 1 megastars. All this and more is discussed in…
Data loss, Global Security News, Guest blog, Law & order, Podcast, Security threats
Smashing Security podcast #440: How to hack a prison, and the hidden threat of online checkouts
A literal insider threat: we head to a Romanian prison where “self-service” web kiosks allowed inmates to run wild. Then we head to the checkout aisle to ask why JavaScript on payment pages went feral, and how new PCI DSS rules are finally muzzling Magecart-style skimmers. Plus: Graham reveals his new-found superpower with Keyboard Maestro,…
data breach, Data loss, Global Security News, Guest blog, Law & order
John Bolton charged over classified emails after Iranian hack of his AOL account
Former US national security adviser John Bolton is the latest in a line of Donald Trump’s critics to find themselves on the sharp end of charges from the US Department of Justice. Bolton, who left the White Hose in 2021 and wrote a tell-all memoir describing Trump as unfit for office and “stunningly uninformed,” has…
data breach, Data loss, Global Security News, Guest blog, Law & order
Hundreds of masked ICE agents doxxed by hackers, as personal details posted on Telegram
Hundreds of US government officials working for the FBI, ICE, and Department of Justice have had their personal data leaked by a notorious hacking group. Read more in my article on the Hot for Security blog.
BreachForums, data breach, Data loss, Global Security News, Guest blog, Law & order
BreachForums seized, but hackers say they will still leak Salesforce data
Read more in my article on the Hot for Security blog.
Data loss, Global Security News, malware, Podcast, privacy, Ransomware
Smashing Security podcast #438: When your mouse turns snitch, and hackers grow a conscience
Your computer’s mouse might not be as innocent as it looks – and one ransomware crew has a crisis of conscience that nobody saw coming. We talk about how something as ordinary as a web page could turn your mouse into a surprisingly nosey neighbour, and why ransomware gangs need to think carefully about their…
data breach, Data loss, Global Security News, Guest blog, Salesforce, vishing
Salesforce data breach: what you need to know
The Scattered LAPSUS$ Hunters hacking group claims to have accessed data from around 40 customers of Salesforce, the cloud-based customer relationship management service, stealing almost one billion records. Read more in my article on the Fortra blog.
data breach, Data loss, discord, Global Security News, Guest blog
Discord users’ data stolen by hackers in third-party data breach
Discord has confirmed that users who contacted its customer support service have had their data stolen by hackers, who have attempted to extort a ransom from the company. Read more in my article on the Hot for Security blog.
AI, data breach, Data loss, Global Security News, Podcast, vulnerability
Smashing Security podcast #437: Salesforce’s trusted domain of doom
Researchers uncovered a security flaw in Salesforce’s shiny new Agentforce. The vulnerability, dubbed “ForcedLeak”, let them smuggle AI-read instructions in via humble Web-to-Lead form… and ended up spilling data for the low, low price of five dollars. And we discuss why data breach communicationss still default to “we take security seriously” while quietly implying “assume…
Android, Data loss, encryption, Exploits, Global Security News, Guest blog, iOS
Your favourite phone apps might be leaking your company’s secrets
Most of the apps on your phone are talking to a server somewhere – sending and receiving data through messages sent through APIs, the underlying infrastructure that allows apps to communicate. And here’s the problem – hackers have determined that the APIs of mobile apps, when left visible and exploitable, can be a goldmine. Read…
Data loss, Global Security News, Law & order, malware, Podcast, Ransomware
Smashing Security podcast #436: The €600,000 gold heist, powered by ransomware
Ransomware doesn’t just freeze computers – it can silence alarms too. And when the Natural History Museum in Paris went dark, thieves helped themselves to €600,000 worth of gold in a daring late-night heist. Meanwhile, developers have a new headache: a worm dubbed “Shai Hulud” has wriggled its way through more than 180 npm packages,…
data breach, Data loss, Global Security News, Guest blog, malware, Ransomware
INC ransomware: what you need to know
INC is the name of a ransomware-as-a-service (RaaS) operation that first appeared in late summer 2023. Learn more about what it has been up to, and how to protect against its attacks, in my article on the Fortra blog.
data breach, Data loss, Global Security News, Guest blog, Law & order, privacy
Vastaamo psychotherapy hack: US citizen charged in latest twist of notorious data breach
28-year-old Daniel Lee Newhard, an American citizen living in Estonia, has been charged in relation to the notorious hack of Vastaamo, the biggest data breach in Finnish history. Read more in my article on the Hot for Security blog.
BreachForums, Data loss, Global Security News, Guest blog, Law & order, malware
“Pompompurin” resentenced: BreachForums creator heads back behind bars
Conor Brian Fitzpatrick, the creator of the notorious BreachForums hacking forum, has been resentenced to three years in prison after a US appeals court overturned his prior sentence of time served and 20 years of supervised release. Read more in my article on the Hot for Security blog.
data breach, Data loss, Global Security News, Gucci, Guest blog, Ransomware
Luxury fashion brands Gucci, Balenciaga and Alexander McQueen hacked – customer data stolen
Luxury fashion group Kering – owner of the prestigious Gucci, Balenciaga, and Alexander McQueen brands, amongst others – has confirmed that hackers stole customer data from its systems in June 2025. Read more in my article on the Hot for Security blog.
data breach, Data loss, Global Security News, Guest blog, rail
British rail passengers urged to stay on guard after hack signals failure
Passengers of the UK’s state-owned London North Eastern Railway (LNER) have been warned to be vigilant after cybercriminals accessed traveller’s contact details and some information about past journeys. Read more in my article on the Hot for Security blog.
AI, Data loss, Global Security News, Law & order, Podcast, privacy
Smashing Security podcast #434: Whopper Hackers, and AI Whoppers
Ever wondered what would happen if Burger King left the keys to the kingdom lying around for anyone to use? Ethical hackers did – and uncovered drive-thru recordings, hard-coded passwords, and even the power to open a Whopper outlet on the moon. Meanwhile, over in Silicon Valley, one AI wunderkind managed to turn a $7…
Data loss, Global Security News, Guest blog, Law & order, malware, Ransomware
US charges suspected ransomware kingpin, and offers $10 million bounty for his capture
A US federal court has unssealed charges against a Ukrainian national who authorities allege was a key figure behind several strains of ransomware, including LockerGoga, MegaCortex, and Nefilim. Read more in my article on the Fortra blog.
data breach, Data loss, Global Security News, Guest blog, RansomHub, Ransomware
Lovesac warns customers their data was breached after suspected RansomHub attack six months ago
American furniture maker Lovesac, known for its modular couches and comfy beanbags, has warned customers that their data was breached by hackers earlier this year, and that they should remain vigilant to the threat of identity theft. Read more in my article on the Hot for Security blog.
critical infrastructure, Data loss, Global Security News, Guest blog, Law & order, Security threats
Germany charges hacker with Rosneft cyberattack in latest wake-up call for critical infrastructure
A 30‑year‑old man has been charged with launching a cyberattack on the German subsidiary of Russia’s state-owned oil giant Rosneft. The cyberattack, which happened in March 2022 in the aftermath of Russia’s invasion of Ukraine, crippled the company’s operations and cost millions of euros in damages. Read more in my article on the Exponential-e blog.
data breach, Data loss, Global Security News, malware, Ransomware
Sweden scrambles after ransomware attack puts sensitive worker data at risk
Municipal government organisations across Sweden have found themselves impacted after a ransomware attack at a third-party software service supplier. Read more in my article on the Hot for Security blog.
Data loss, encryption, Global Security News, Microsoft, phishing, Podcast
Smashing Security podcast #432: Oops! I auto-filled my password into a cookie banner
We unpack how some password managers can be tricked into coughing up your secrets, with a clickjacking sleight-of-hand, what website owners can do to prevent it, and how to lock down your personal password vault. Then we time-hope to the post-quantum scramble: “harvest-now, decrypt later”, Microsoft’s 2033 quantum-safe pledge, and whether your printer will survive…
data breach, Data loss, Global Security News, Guest blog, malware, Ransomware
Cephalus ransomware: What you need to know
Cephalus is a relatively new ransomware operation that emerged in mid-2025, and has already been linked to a wave of high-profile data leaks. Read more about it in my article on the Fortra blog.
Data loss, Global Security News, Guest blog, malware, Ransomware
Blue Locker ransomware hits critical infrastructure – is your organisation ready?
Critical infrastructure organisations are once again being warned of the threat posed by malicious cybercriminals, following a ransomware attack against a state-owned energy company in Pakistan. Read more in my article on the Exponential-e blog.
Data loss, Global Security News, Guest blog, malware, Ransomware
Warlock ransomware: What you need to know
The Warlock ransomware has hit a number of organisations including government agencies and departments, and most recently UK-based telecoms firm Colt. Read more in my article on the Fortra blog.
data breach, Data loss, Global Security News, iOS, privacy
TeaOnHer copies everything from Tea – including the data breaches
TeaOnHer hasn’t stopped at copying the functionality of the original Tea app (albeit skewed towards men rating women). It also appears to have carelessly mimicked the Tea dating advice app’s recklessness when it comes to data security. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, Law & order, malware, Ransomware
Ransomware plunges insurance company into bankruptcy
Collapsed company’s founder says that its fortunes were hampered by the refusal of authorities to release the criminals’ seized funds to victims. Read more in my article on the Fortra blog.
data breach, Data loss, Global Security News, Guest blog, Russia, submarine
Ukraine claims to have hacked secrets from Russia’s newest nuclear submarine
Ukraine’s Defence Intelligence agency (HUR) claims that its hackers have successfully stolen secret files and classified data on a state-of-the-art Russian nuclear submarine, the “Knyaz Pozharsky.” Read more in my article on the Hot for Security blog.
data breach, Data loss, Global Security News, hospital, medical, privacy
Hospital fined after patient data found in street food wrappers
A hospital in Thailand has been fined after patient’s printed records were recycled as snack bags to hold crispy crepes.
data breach, Data loss, Global Security News, Podcast, privacy
Smashing Security podcast #428: Red flags, leaked chats, and a final farewell
The viral women-only dating safety app Tea, built to flag red flags, gets flagged itself – after leaking over 70,000 private images and chat logs. We are talking full-on selfies, ID docs, private DMs, and a dash of 4chan creepiness. Yikes. Plus, Carole takes us down memory lane as she hangs up her co-host mic…
data breach, Data loss, Europe, Global Security News, Guest blog, submarine
French submarine secrets surface after cyber attack
European defence giant Naval Group has confirmed that it is investigating an alleged cyber attack which has seen what purports to be sensitive internal data published on the internet by hackers. Read more in my article on the Hot for Security blog.
data breach, Data loss, gambling, Global Security News, Paddy Power
Paddy Power and BetFair have suffered a data breach
Paddy Power and BetFair have warned customers that “an unauthorised third party” gained access to “limited betting account information” relating to up to 800,000 of their customers.
Android, data breach, Data loss, Global Security News, privacy, vulnerability
Catwatchful stalkerware app spills secrets of 62,000 users – including its own admin
Another scummy stalkerware app has spilled its guts, revealing the details of its 62,000 users – and data from thousands of victims’ infected devices.
Data loss, Global Security News, Guest blog, Hunters International, malware, Ransomware
Hunters International ransomware group shuts down – but will it regroup under a new guise?
The notorious Hunters International ransomware-as-a-service operation has announced that it has shut down, in a message posted on its dark web leak site. In a statement on its extortion site, the ransomware group says that it has not only “decided to close the Hunters International project” but is also offering free decryption tools to its…
data breach, Data loss, Global Security News, Guest blog, malware, Ransomware
Swiss government warns attackers have stolen sensitive data, after ransomware attack at Radix
The Swiss government has issued a warning after a third-party service provider suffered a ransomware attack, which saw sensitive information stolen from its systems and leaked onto the dark web. Read more in my article on the Fortra blog.
BreachForums, data breach, Data loss, Global Security News, Guest blog, Law & order
BreachForums broken up? French police arrest five members of notorious cybercrime site
Suspected high-ranking members of one of the world’s largest online marketplaces for leaked data have been arrested by French police. Read more in my article on the Hot for Security blog.
Data loss, Global Security News, Guest blog, malware, Ransomware
SafePay ransomware: What you need to know
SafePay is a relatively new ransomware that is making a big impact. Find out how it is different from other ransomware, and read more in my article on the Fortra blog.
Data loss, Global Security News, insurance, Ransomware, Scattered Spider
Aflac, one of the USA’s largest insurers, is the latest to fall “under siege” to hackers
The Wall Street Journal reports that Aflac is investigating a breach that may have exposed claims information, health details, Social Security numbers, and other personal data.
data breach, Data loss, Global Security News, malware, Marks and Spencer, Ransomware
Marks & Spencer ransomware attack was good news for other retailers
When Marks & Spencer paused online orders after it was hit by ransomware, it was bad news for them… but GOOD news for other big online retailers. Fashion rivals like Next, John Lewis, and Zara saw a nice little bump while M&S sales floundered.
data breach, Data loss, Global Security News, Guest blog, Krispy Kreme
Krispy Kreme hack exposed sensitive data of over 160,000 people
Krispy Kreme, the dispenser of delectable doughnuts, has revealed that an astonishingly wide range of personal information belonging to past and present employees, as well as members of their families, was accessed by hackers during a cyber attack last year. Read more in my article on the Hot for Security blog.
data breach, Data loss, gchq, Global Security News, Law & order, Podcast
Smashing Security podcast #422: The curious case of the code copier
A GCHQ intern forgets the golden rule of spy school — don’t take the secrets home with you — and finds himself swapping Cheltenham for a cell. Meanwhile, an Australian hacker flies too close to the sun, hacks his way into a US indictment, and somehow walks free… only to get booted back Down Under.…
data breach, Data loss, Global Security News
Yes, the Co-op lost your data. Have a £10 shopping voucher
The Co-op is offering a £10 shopping discount to members after a cyber-attack saw hackers steal personal data including names, home address, email addresses, and membership card numbers.
data breach, Data loss, Global Security News, malware, Ransomware
Infecting insurance firms with ransomware… for dummies
Is it any wonder that ransomware gangs are targeting cyberinsurance companies? There is *so* much valuable data to steal, which can help them earn even more money from more victims.
data breach, Data loss, Global Security News, Guest blog, malware, Ransomware
Bert ransomware: what you need to know
Bert is a recently-discovered strain of ransomware that encrypts victims’ files and demands a payment for the decryption key. Read more in my article on the Fortra blog.
data breach, Data loss, Global Security News, Guest blog
Adidas customers’ personal information at risk after data breach
Lovers of Adidas clothes would be wise to be on their guard against phishing attacks, after the German sportswear giant revealed that a cyber attack had exposed the personal information of customers. Read more in my article on the Hot for Security blog.
data breach, Data loss, Exploits, Global Security News, Guest blog, malware, Ransomware, vishing
3AM ransomware attack poses as a call from IT support to compromise networks
Cybercriminals are getting smarter. Not by developing new types of malware or exploiting zero-day vulnerabilities, but by simply pretending to be helpful IT support desk workers. Find out how they do it in my article on the Tripwire State of Security blog.
critical infrastructure, data breach, Data loss, Global Security News, Instagram, Law & order, Podcast, Portugal, Smashing Security, spain
Smashing Security podcast #418: Grid failures, Instagram scams, and Legal Aid leaks
In this week’s episode, Graham investigates the mysterious Iberian Peninsula blackout (aliens? toaster? cyberattack?), Carole dives in the UK legal aid hack that exposed deeply personal data of society’s most vulnerable, and Dinah Davis recounts how Instagram scammers hijacked her daughter’s account – and how a parental control accidentally saved the day.
data breach, Data loss, Global Security News, Guest blog, Healthcare, North America, vulnerability
Prescription for disaster: Sensitive patient data leaked in Ascension breach
Ascension, one of the largest private healthcare companies in the United States, has confirmed that the personal data of some 437,329 patients has been exposed following an attack by cybercriminals. Read more in my article on the Fortra blog.
data breach, Data loss, Global Security News, Guest blog, LockBit, Ransomware
LockBit ransomware gang breached, secrets exposed
Oh dear, what a shame, never mind. Read more in my article on the Tripwire State of Security blog.
data breach, Data loss, Donald Trump, Global Security News, Guest blog, Law & order
Hackers hit deportation airline GlobalX, leak flight manifests, and leave an unsubtle message for “Donnie” Trump
GlobalX Airlines, a charter airline being used by the US government for deportation flights, has been attacked by hacktivists who have made off with what they claim are detailed flight records and passenger manifests. Read more in my article for the Hot for Security blog.
Data loss, Global Security News, Law & order, malware, Marks and Spencer, Podcast, Ransomware, Smashing Security
Smashing Security podcast #416: High street hacks, and Disney’s Wingdings woe
Brits face empty shelves and suspended meal deals as cybercriminals hit major high street retailers, and a terminated Disney employee gets revenge with a little help with Wingdings. Plus Graham challenges Carole to a game of “Malware or metal?”, and we wonder just happens when you have sex on top of a piano? All this…
data breach, Data loss, Global Security News, Guest blog, Spyware
21 million employee screenshots leaked in bossware breach blunder
If you thought only your boss was peeking at your work screen, think again. Employee-monitoring tool Work Composer has committed a jaw-dropping blunder, leaving a treasure trove of millions of workplace screenshots openly accessible on the internet with no encryption in place, and no password required. Read more in my article on the Hot for…
Data loss, Global Security News, Guest blog, malware, sim swap, South Korea
Hackers access sensitive SIM card data at South Korea’s largest telecoms company
Mobile network operator SK Telecom, which serves approximately 34 million subscribers in South Korea, has confirmed that it suffered a cyber attack earlier this month that saw malware infiltrate its internal systems, and access data related to customers’ SIM cards. Read more in my article on the Hot for Security blog.
data breach, Data loss, Global Security News, Guest blog, insurance
Insurance firm Lemonade warns of breach of thousands of driving license numbers
A data breach at insurance firm Lemonade left the details of thousands of drivers’ licenses exposed for 17 months. According to the company, on March 14 2025 Lemonade learnt that a vulnerability in its online car insurance application process contained a vulnerability that was likely to have exposed “certain driver’s license numbers for identifiable individuals.”…
data breach, Data loss, Global Security News, Guest blog, Ransomware
RansomHouse ransomware: what you need to know
RansomHouse is a cybercrime operation that follows a Ransomware-as-a-Service (RaaS) business model, where affiliates (who do not require technical skills of their own) use the ransomware operator’s infrastructure to extort money from victims. Read more in my article on the Fortra blog.
data breach, Data loss, Global Security News, Guest blog, malware, Medusa, NASCAR, North America, Ransomware
Medusa ransomware gang claims to have hacked NASCAR
The Medusa ransomware-as-a-service (RaaS) claims to have compromised the computer systems of NASCAR, the United States’ National Association for Stock Car Auto Racing, and made off with more than 1TB of data. Read more in my article on the Hot for Security blog.
CryptoCurrency, data breach, Data loss, Global Security News, Guest blog, Law & order, phishing, Scattered Spider, sim swap
King Bob pleads guilty to Scattered Spider-linked cryptocurrency thefts from investors
A Florida man, linked to the notorious Scattered Spider hacking gang, has pleaded guilty to charges related to cryptocurrency thefts which have netted hundreds of thousands of dollars. Read more in my article on the Hot for Security blog.
Cybersecurity, Data loss, Data Security, file backup, Global Security News, Intellectual Property, Security, Security Awareness, Security Boulevard (Original), Social - Facebook, Social - LinkedIn, Social - X
Corporate Layoffs Put Company IP at Risk
With corporate layoffs and government workforce reductions frequently making headlines, leaders often underestimate the potential for massive data loss and intellectual property liability. The post Corporate Layoffs Put Company IP at Risk appeared first on Security Boulevard.
data breach, Data loss, Global Security News, Guest blog, Healthcare, NHS, Ransomware
£3 million fine for healthcare MSP with sloppy security after it was hit by ransomware attack
A UK firm has been hit by a £3.07 million fine after being hit by a ransomware attack that exposed sensitive data related to almost 80,000 people, and disrupted NHS services. Read more in my article on the Exponential-e blog.
data breach, Data loss, Global Security News, Law & order, malware, Podcast, postal, Ransomware, Smashing Security, snail mail
Smashing Security podcast #408: A gag order backfires, and a snail mail ransom demand
What happens when a healthcare giant’s legal threats ignite a Streisand Effect wildfire… while a ransomware gang appears to ditch the dark web for postage stamps? Find out about this, and more, in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault.
Data loss, Global Security News, Guest blog, malware, Ransomware
Cactus ransomware: what you need to know
Cactus is a ransomware-as-a-service (RaaS) group that encrypts victim’s data and demands a ransom for a decryption key. Read more about it in my article on the Tripwire State of Security blog.
data breach, Data loss, Global Security News, Guest blog, Law & order, malware, North America, phobos, Ransomware
US charges two Russian men in connection with Phobos ransomware operation
Roman Berezhnoy and Egor Nikolaevich Glebov are alleged to have extorted over US $16 million in ransom payments using the Phobos ransomware, impacting over 1000 organisations in the United States. Read more in my article on the Hot for Security blog.
data breach, Data loss, Global Security News, Guest blog, Laptop, Law & order, North Korea, remote working, Security threats
US woman faces years in federal prison for running laptop farm for N Korean IT workers
Christian Marie Chapman, of Litchfield Park, Arizona, helped generate over US $17 million for North Korea after over 300 US companies unwittingly hired staff believing them to be US citizens. Read more in my article on the Hot for Security blog.
AI, Artificial Intelligence, data breach, Data loss, Global Security News, Law & order, malware, Podcast, Ransomware, sim swap, Smashing Security, Twitter
Smashing Security podcast #404: Podcast not found
The story of how hackers managed to compromise the US Government’s official SEC Twitter account to boost the price of Bitcoins, AI isn’t helping reduce the rife conspiracy theories inside classrooms, and is the funeral bell tolling for ransomware? All this and more is discussed in the latest edition of the “Smashing Security” podcast by…
data breach, Data loss, Global Security News, Guest blog, Taliban
Secret Taliban records published online after hackers breach computer systems
The Taliban government of Afghanistan is reeling after unidentified hackers successfully carried out a massive cyber attack against its computer systems and published over 50GB of stolen documents and files online. Read more in my article on the Hot for Security blog.
data breach, Data loss, Global Security News, Guest blog, law, Ransomware
Data breaches at UK law firms are on the rise, research reveals
British legal professionals have seen a “significant surge” in data breaches, according to new research from NetDocuments, a firm that provides a cloud-based content management platform for the legal sector. Read more in my article on the Tripwire State of Security blog.
Coinbase, data breach, Data loss, Global Security News, malware, Podcast, powerschool, QR code, Ransomware, Smashing Security, VPN
Smashing Security podcast #403: Coinbase crypto heists, QR codes, and ransomware in the classroom
In episode 403 of “Smashing Security” we dive into the mystery of $65 million vanishing from Coinbase users faster than J-Lo slipped into Graham’s DMs, Geoff gives a poor grade for PowerSchool’s security, and Carole takes a curious look at QR codes. All this and more is discussed in the latest edition of the “Smashing…
Botnet, Data loss, Denial of Service, Global Security News, kidnap, Law & order, malware, Operating Systems, Podcast, privacy, Remote access trojan, Smashing Security, Social networks, Spyware
Smashing Security podcast #402: Hackers get hacked, the British Museum IT shutdown, and social media kidnaps
What happens when eager computer enthusiasts unknowingly download a trojanized hacking tool and find themselves on the wrong side of cybersecurity? A former employee’s actions led to chaos and raise urgent questions about the security of cultural treasures. And join us as we explore the alarming trend of social media influencers staging fake kidnappings. All…
